Secure Sharing: Share an Encrypted Vault

Create a one-time sharing phrase for someone you trust. Vaultaire encrypts the shared files before they leave your device, sends the encrypted data through iCloud, and decrypts it on the recipient's device. The owner remains the only writer and can revoke future access.

Secure Sharing gives one recipient read-only access to an encrypted copy of a vault. The recipient needs Vaultaire, an iCloud sign-in, and the unused sharing phrase. The phrase is separate from your pattern and recovery phrase.

What Is Secure Sharing?

Secure Sharing is for sending a collection of private files without placing readable copies in cloud storage. Vaultaire encrypts the shared payload on the owner's device. CloudKit stores the encrypted payload and the records needed to claim, update, and revoke the share. The recipient's device decrypts the files locally.

The sharing phrase is a one-time claim credential. It identifies the share and supplies the material needed to open it. Once one recipient claims the share, the same phrase cannot be used to claim it again. Create a separate share for each person.

iCloud Required

Vaultaire does not require a separate account or email address. Secure Sharing does use Apple's CloudKit, so both devices must be signed in to iCloud and need a network connection to create or claim the share.

How Sharing Works, Step by Step

Each share moves through four clear steps.

Step 1: You Generate a Sharing Phrase

Inside an owned vault, tap “Share.” Vaultaire generates a phrase that is separate from your unlock pattern and recovery phrase. You can also set an expiration date, an open limit, and in-app export and screenshot policies.

Step 2: You Communicate the Phrase

Send the phrase through a channel you trust, such as in person, by phone, or in an end-to-end encrypted message. Anyone who gets the unused phrase may be able to claim the share.

Step 3: The Recipient Enters the Phrase

The recipient opens Vaultaire, chooses “Open Shared Vault,” and enters the phrase. Vaultaire claims the share through CloudKit, downloads the encrypted payload, and decrypts it on the device. The phrase is spent after the successful claim.

Step 4: The Recipient Gets Read-Only Updates

The owner remains the only writer. When the owner changes the vault, Vaultaire can send encrypted updates through CloudKit. The recipient can view the current shared contents but cannot add files back to the owner's vault.

The Controls You Keep

Vaultaire provides practical limits for normal use. These policies are enforced by the app. They are not digital rights management and cannot control data after it leaves Vaultaire.

Time-Limited
Set Expiration Dates
Count-Limited
Limit Number of Opens
Revocable
Stop Future Access

Expiration Dates

Set a date after which Vaultaire should stop opening the shared vault. The app and its CloudKit records enforce the policy. Device clocks, cached data, and software outside Vaultaire limit what any expiry control can guarantee.

Open Limits

Set how many successful opens Vaultaire allows. The count survives normal app relaunches and re-entry. It is still a client-enforced limit, not proof that a recipient did not retain information they already viewed.

Export Prevention

When exports are disabled, Vaultaire removes its normal save and share actions for the recipient. Screenshot protection uses the controls available to the app and can lock the shared vault when capture is detected. These measures do not stop another camera, a modified device, operating-system behavior, or content already saved outside Vaultaire.

Revoking Access

Tap “Revoke Access” to record the revocation in CloudKit. Vaultaire keeps a durable retry record if the owner's device is offline. A recipient device learns about the revocation when it next reaches CloudKit. Revocation stops later app access, but it cannot erase files or information the recipient already moved outside Vaultaire.

Automatic Synchronization

Secure Sharing is more than a one-time export. The owner can publish encrypted changes, and the recipient can receive them the next time Vaultaire checks the share online. CloudKit delivery is eventually consistent, so updates and revocations may not appear immediately.

The owner remains the source of truth. Recipients have read-only access and cannot contribute files or edit the owner's vault.

Owner Writes, Recipient Reads

Shared vaults are deliberately one-way. The owner publishes changes. The recipient views them under the selected app policies.

The Security Behind Sharing

Secure Sharing separates file encryption from the operational records needed to deliver a share.

End-to-End Encryption

Vaultaire encrypts file contents on the owner's device and decrypts them on the recipient's device. The sharing phrase is not stored in CloudKit. CloudKit receives encrypted payloads that it cannot turn into readable files without the required key material.

Separate Key Hierarchy

The sharing phrase uses a separate key path from your pattern and recovery phrase. Giving someone a sharing phrase does not reveal either personal credential.

One-Time Claim

The phrase can claim its share once. After a successful claim, Vaultaire uses separate per-share sync material for updates. A saved copy of the phrase cannot claim the same share on another device.

Cloud Boundary

CloudKit needs operational records for claim state, policy, updates, and revocation. Apple can observe record metadata such as sizes and timestamps. It does not receive the sharing phrase or readable file contents.

Frequently Asked Questions

Is the sharing phrase the same as the recovery phrase?

No. A recovery phrase restores your own vault. A sharing phrase is a separate, one-time credential used to claim one shared vault. It does not reveal your pattern or recovery phrase.

What happens if the sharing phrase is intercepted?

Someone who obtains an unused sharing phrase may claim that share. Send it through a trusted channel. If you suspect it was exposed, revoke the share. The revocation reaches a recipient device when it checks CloudKit online.

Can I share a vault with multiple people?

Yes. Create a separate share and one-time phrase for each recipient. Each share has its own policy and can be revoked separately.

Does the recipient need to sign in?

Vaultaire has no separate account sign-up, but sharing uses CloudKit. The recipient needs Vaultaire and must be signed in to iCloud on the device.

What happens when I revoke a share?

Vaultaire records the owner's revocation in CloudKit and retries if the network is unavailable. A recipient device must come online and check the share before it learns about the revocation. Revocation cannot erase content already saved outside Vaultaire.

Can Vaultaire see what I share?

Shared files are encrypted on the owner's device and decrypted on the recipient's device. CloudKit stores encrypted payloads plus operational records needed for claiming, syncing, and revoking a share. Apple can see record metadata such as sizes and timestamps, but not the file contents or sharing phrase.

Share an Encrypted, Read-Only Vault

Keep file contents encrypted in transit and storage while the recipient reads them in Vaultaire.

Download Vaultaire Free